Back to Malware Drops

4f75eec50688856480316bb404ba90d33d5de43ded45066b5a3d9b3fb7cc8720

MD5480cca2893407eb1d59970c9ca8ab831
SSDEEP48:ELnZxiSbGVQmGf/LU8fGUa/U/BqxGDf/LLj/U/B0:ix5bsQmGfQQGUa8sGDfD8C
File Typetext/x-script
Size2.3 KB
Sources77
Downloads0
First SeenJul 19, 2018
Last SeenSep 18, 2018
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (1)

  • ddos[.]sddos[.]xyz

url (2)

  • hxxp://ddos[.]sddos[.]xyz:8181/systems1
  • hxxp://ddos[.]sddos[.]xyz:9960/systems